Skip to content

The audit log

The Audit log lists every record of your organization: what agents did, approvals, rule changes, people, settings, gates and the evidence itself.

  • Agent actions that match a rule: the request, the rule and rule set version, the decision (allow, ask, deny), and the result. Actions that match no rule are not recorded.
  • Approvals: who approved or denied, in which channel (web, Slack, Teams, email), and when. An expired request counts as denied.
  • Admin events: rule changes with hashes before and after, gates connected and disconnected, role changes, offboarding, settings changes.
  • Sessions: who started an agent, as which Linux user, with which rule set.

Values that look like secrets are masked before they are recorded. Request bodies and command output are never in the record.

Gates write agent actions into their own chain, signed with the gate’s key; the server writes everything else into your organization’s chain. See Verify the evidence.

Type in the search field: an agent, a host, a customer id, a person. Every word of three characters or more must match. Combine it with filters:

  • Event type, several at once: agent actions, approvals, rule tests, rules, people, settings, gates, evidence.
  • Outcome: the rule’s (allow, ask, deny) or the approval’s (approved, denied).
  • Channel: web, Slack, Teams, email, CLI.
  • Agent, approver and date.

Results are newest first, with the total. Load more fetches the next page. The search and filters are in the page’s address, so you can send a colleague the same view.

Each result shows its time, agent, action, outcome and approver, and whether it checks out in its chain: Verified, Broken or Not checked. Searching never changes the log.

Agent actions come from the gates’ chains, which admins and auditors see. Everyone else sees the organization’s chain.

Admins and auditors click Export to download exactly the current result set:

  • JSON, to check it: each record exactly as it was signed, with its hashes and the public keys. Anyone can check it offline with noset verify.
  • CSV, for spreadsheets: one row per record, with its hash, the previous hash and the signature as columns.

Every export is itself recorded in the audit log.